Microsoft code of conduct draws line on AI cyberattack capability
The company's Humanist AI Code of Conduct separates defensive security research from operational attack capability, and adds chain-of-command and safety constraints.
By The Agentic Times ·

Microsoft has published an internal code of conduct for its artificial intelligence work that sets boundaries around cyberattack capability, according to a report by SecurityWeek on 15 September 2026.
The document, described by SecurityWeek as the Humanist AI Code of Conduct, draws a line between defensive cyber research and operational attack capability. In other words, it distinguishes work intended to find and fix weaknesses from work that would produce a usable offensive tool. The code also covers what SecurityWeek describes as chain of command and safety constraints, meaning rules about who authorises particular kinds of work and limits placed on what systems may do.
For teams building AI agents — software that can plan and carry out multi-step tasks with limited human supervision — the defensive-versus-operational distinction is the part that matters most in practice. Security tooling increasingly sits close to that line. A model that can reason about a vulnerability well enough to help patch it can often reason about it well enough to help exploit it. A written policy that names the boundary is, at minimum, an admission by a major vendor that the boundary is real and needs to be managed rather than assumed away.
The SecurityWeek report is the only source for this account, and the summary available does not set out the full text of the code, the scope of products or teams it applies to, how compliance is checked, or what happens when a project sits ambiguously on the boundary. It also does not state whether the code is binding on Microsoft's partners or customers, or only on its own staff and systems. Those details would determine how much the document changes day-to-day engineering decisions.
Codes of conduct of this kind are voluntary commitments. They are not law, and they are not audited by an outside body unless a company chooses to invite one. Their value depends heavily on the enforcement machinery behind them — the chain-of-command element referred to in the report suggests Microsoft has at least attempted to specify who decides.
The Agentic Times has not independently reviewed the code of conduct. Readers wanting the specifics should consult Microsoft's own publication of the document. We will report further if the company sets out how the constraints are applied to its agentic products, including any review process for security research that touches operational attack techniques.
Sources
- securityweek.comhttps://securityweek.com/microsoft-ai-code-of-conduct-sets-cyberattack-boundaries-chain-of-command-safety-constraints
